Ethical Hacker ICT Professionals
SaveWhat Does an {{ profession.preferred_title|title }} Do?
Ethical hackers perform security vulnerability assessments and penetration tests in accordance with industry-accepted methods and protocols. They analyse systems for potential vulnerabilities that may result from improper system configuration, hardware or software flaws, or operational weaknesses.
Resource recommendations may include affiliate links. Learn more
Where Do I Start?
Computer Forensics
The process of examining and recovering digital data from sources for legal evidence and crime investigation.
Sign up to trackReady to go deeper? Pick up to 3 skills to focus on from the list below.
These are common skills for this role. Real-world experience matters more than ticking every box — use this as a guide, not a checklist.
Skills You Need to Become an Ethical Hacker
Essential Skills
Essential Skills
-
EssentialComputer Forensics knowledge
The process of examining and recovering digital data from sources for legal evidence and crime investigation.
Recommended Books
4 books -
EssentialWeb Application Security Threats knowledge
The attacks, vectors, emergent threats on websites, web applications and web services, the rankings of their severity identified by dedicated communities such as OWASP (Open Web Application Security Project).
-
EssentialLegal Requirements Of Ict Products knowledge
The international regulations related to the development and use of ICT products.
Recommended Books
3 books -
EssentialTools For Ict Test Automation knowledge
The specialised software to execute or control tests and compare predicted testing outputs with actual testing results such as Selenium, QTP and LoadRunner
No book recommendations available yet.
-
EssentialCyber Attack Counter-Measures knowledge
The strategies, techniques and tools that can be used to detect and avert malicious attacks against organisations' information systems, infrastructures or networks.
No book recommendations available yet.
-
EssentialSoftware Anomalies knowledge
The deviations of what is standard and exceptional events during software system performance, identification of incidents that can alter the flow and the process of system execution.
No book recommendations available yet.
-
EssentialPenetration Testing Tool knowledge
The specialised ICT tools which test security weaknesses of the system for potentially unauthorised access to system information such as Metasploit, Burp suite and Webinspect.
No book recommendations available yet.
-
EssentialAddress Problems Critically skill
Identify the strengths and weaknesses of various abstract, rational concepts, such as issues, opinions, and approaches related to a specific problematic situation in order to formulate solutions and alternative methods …
Course recommendations coming soon.
-
EssentialExecute Ict Audits skill
Organise and execute audits in order to evaluate ICT systems, compliance of components of systems, information processing systems and information security. Identify and collect potential critical issues and recommend solutions …
Course recommendations coming soon.
-
EssentialExecute Software Tests skill
Perform tests to ensure that a software product will perform flawlessly under the specified customer requirements, using specialised software tools. Apply software testing techniques and tools in order to identify …
Course recommendations coming soon.
-
EssentialMonitor System Performance skill
Measure system reliability and performance before, during and after component integration and during system operation and maintenance. Select and use performance monitoring tools and techniques, such as special software.
Course recommendations coming soon.
-
EssentialProvide Technical Documentation skill
Prepare documentation for existing and upcoming products or services, describing their functionality and composition in such a way that it is understandable for a wide audience without technical background and …
Course recommendations coming soon.
-
EssentialAnalyse The Context Of An Organisation skill
Study the external and internal environment of an organisation by identifying its strengths and weaknesses in order to provide a base for company strategies and further planning.
Course recommendations coming soon.
-
EssentialDevelop Code Exploits skill
Create and test software exploits in a controlled environment to uncover and check system bugs or vulnerabilities.
Course recommendations coming soon.
-
EssentialIdentify Ict Security Risks skill
Apply methods and techniques to identify potential security threats, security breaches and risk factors using ICT tools for surveying ICT systems, analysing risks, vulnerabilities and threats and evaluating contingency plans.
Course recommendations coming soon.
-
EssentialIdentify Ict System Weaknesses skill
Analyse the system and network architecture, hardware and software components and data in order to identify weaknesses and vulnerability to intrusions or attacks.
Course recommendations coming soon.
-
EssentialPerform Security Vulnerability Assessments skill
Execute types of security testing, such as network penetration testing, wireless testing, code reviews, wireless and/or firewall assessments in accordance with industry-accepted methods and protocols to identify and analyse potential …
Course recommendations coming soon.
Optional Skills (5 of {{ profession.optional_skills|length }} displayed)
-
OptionalInternet Of Things knowledge
The general principles, categories, requirements, limitations and vulnerabilities of smart connected devices (most of them with intended internet connectivity).
Recommended Books
5 book{{ skill.books|length|pluralize }} -
OptionalOrganisational Resilience knowledge
The strategies, methods and techniques that increase the organisation's capacity to protect and sustain the services and operations that fulfil the organisational mission and create lasting values by effectively addressing …
Recommended Books
4 book{{ skill.books|length|pluralize }}Building Organizational Resilience -
OptionalOutsourcing Model knowledge
The outsourcing model consists of principles and fundamentals of service-oriented modelling for business and software systems that allow the design and specification of service-oriented business systems within a variety of …
Recommended Books
3 book{{ skill.books|length|pluralize }} -
OptionalProxy Servers knowledge
The proxy tools which act as an intermediary for requests from users searching for resources e.g. files and web pages from other servers such as Burp, WebScarab, Charles or Fiddler.
-
OptionalSaas (Service-Oriented Modelling) knowledge
The SaaS model consists of principles and fundamentals of service-oriented modelling for business and software systems that allow the design and specification of service-oriented business systems within a variety of …
-
OptionalIct Network Security Risks knowledge
The security risk factors, such as hardware and software components, devices, interfaces and policies in ICT networks, risk assessment techniques that can be applied to assess the severity and the …
Recommended Books
1 book{{ skill.books|length|pluralize }} -
Optional
-
OptionalInformation Confidentiality knowledge
The mechanisms and regulations which allow for selective access control and guarantee that only authorised parties (people, processes, systems and devices) have access to data, the way to comply with …
No book recommendations available yet.
-
OptionalIct Security Legislation knowledge
The set of legislative rules that safeguards information technology, ICT networks and computer systems and legal consequences which result from their misuse. Regulated measures include firewalls, intrusion detection, anti-virus software …
Recommended Books
1 book{{ skill.books|length|pluralize }} -
OptionalIct Encryption knowledge
The conversion of electronic data into a format which is readable only by authorized parties which use key encryption techniques, such as Public Key Infrastructure (PKI) and Secure Socket Layer …
No book recommendations available yet.
-
OptionalInformation Security Strategy knowledge
The plan defined by a company which sets the information security objectives and measures to mitigate risks, define control objectives, establish metrics and benchmarks while complying with legal, internal and …
No book recommendations available yet.
-
OptionalInternet Governance knowledge
The principles, regulations, norms and programs that shape the evolution and use of internet, such as internet domain names management, registries and registrars, according to ICANN/IANA regulations and recommendations, IP …
No book recommendations available yet.
-
OptionalNessus knowledge
The computer program Nessus is a specialised ICT tool which tests security weaknesses of the system for potentially unauthorised access to system information, developed by the software company Tenable Network …
No book recommendations available yet.
-
OptionalNexpose knowledge
The computer program Nexpose is a specialised ICT tool which tests security weaknesses of the system for potentially unauthorised access to system information, developed by the software company Rapid7.
No book recommendations available yet.
-
OptionalOpen Source Model knowledge
The open source model consists of principles and fundamentals of service-oriented modelling for business and software systems that allow the design and specification of service-oriented business systems within a variety …
No book recommendations available yet.
-
OptionalWhitehat Sentinel knowledge
The computer program WhiteHat Sentinel is a specialised ICT tool which tests security weaknesses of the system for potentially unauthorised access to system information, developed by the software company WhiteHat …
No book recommendations available yet.
-
OptionalHybrid Model knowledge
The hybrid model consists of principles and fundamentals of service-oriented modelling for business and software systems that allow the design and specification of service-oriented business systems within a variety of …
-
OptionalCyber Security knowledge
The methods that protect ICT systems, networks, computers, devices, services, digital information and people against illegal or unauthorised use.
No book recommendations available yet.
-
OptionalLevels Of Software Testing knowledge
The levels of testing in the software development process, such as unit testing, integration testing, system testing and acceptance testing.
No book recommendations available yet.
-
OptionalService-Oriented Modelling knowledge
The principles and fundamentals of service-oriented modelling for business and software systems that allow the design and specification of service-oriented business systems within a variety of architectural styles, such as …
No book recommendations available yet.
-
OptionalManage It Security Compliances skill
Guide application and fulfilment of relevant industry standards, best practices and legal requirements for information security.
Course recommendations coming soon.
-
OptionalPerform Project Management skill
Manage and plan various resources, such as human resources, budget, deadline, results, and quality necessary for a specific project, and monitor the project's progress in order to achieve a specific …
Course recommendations coming soon.
-
OptionalSolve Ict System Problems skill
Identify potential component malfunctions. Monitor, document and communicate about incidents. Deploy appropriate resources with minimal outage and deploy appropriate diagnostic tools.
Course recommendations coming soon.
-
OptionalDefine Security Policies skill
Design and execute a written set of rules and policies that have the aim of securing an organisation concerning constraints on behaviour between stakeholders, protective mechanical constraints and data-access constraints.
Course recommendations coming soon.
-
OptionalMaintain Ict Server skill
Diagnose and eliminate hardware faults via repair or replacement. Take preventive measures, review performance, update software, review accessibility.
Course recommendations coming soon.